Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

Crypto ticks up as US-Iran peace deal odds climb

4 minutes ago

Crypto PAC Spending Surges in Texas Runoffs, as Prediction Markets Favor Challengers

7 minutes ago

With Central Bank’s Blessing, Georgia Taps Tether for ‘Official’ Stablecoin

13 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Monday, May 25
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»Perplexity Built a Tool That Checks Your Computer for Infected Software—Without Setting Off the Infection
Cryptocurrency & Free Speech Finance

Perplexity Built a Tool That Checks Your Computer for Infected Software—Without Setting Off the Infection

News RoomBy News Room1 hour agoNo Comments3 Mins Read615 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
Perplexity Built a Tool That Checks Your Computer for Infected Software—Without Setting Off the Infection
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

In brief

  • Bumblebee is a free, open-source tool that checks developer computers for compromised software, browser extensions, and AI connector configs—without running the infected code.
  • Most scanners work by invoking the software they’re checking, which can accidentally trigger the attacks they’re meant to detect.
  • It’s the first open-source scanner to treat MCP config files—the connectors that give AI tools access to your data—as a security surface.

Imagine you suspect someone poisoned a bottle of water in your house. To check, you drink from every bottle. That’s roughly how most security scanners work.

Perplexity just open-sourced a tool called Bumblebee that takes a different approach. It scans developer computers for infected software packages, malicious browser extensions, and compromised AI tool configs—without ever running the code it finds. It reads the code, the ingredient label instead of eating the food.

On May 11, a hacker group called TeamPCP slipped malicious code into over 160 software packages used by millions of developers worldwide—including packages from Mistral AI, UiPath, and a widely used React tool with 12 million weekly downloads. The attack spread automatically the moment developers installed those packages. Perplexity’s Bumblebee could have prevented that, the company says.

Why “read-only” is the whole point

Software packages—especially in the JavaScript world—can run hidden scripts the moment you install them. That’s exactly how the May 11 attack spread so fast. The malicious code fired automatically on install, before anyone noticed anything was wrong.

A scanner that invokes the package manager to check for infections can trigger those same scripts. You go looking for the worm; the worm runs. Bumblebee sidesteps this by never calling any package manager at all. It reads raw metadata files—the records that describe what’s installed—without touching the software itself.

The genuinely new piece is that Bumblebee also scans MCP configuration files—the local files that tell AI assistants like Claude or Cursor which external services they’re allowed to connect to.

MCP connectors give AI tools access to emails, databases, calendars, and code. If an attacker sneaks a malicious connector into that config, your AI assistant could leak credentials or run unauthorized commands in the background. Most security tools aren’t checking for this yet.

Beyond MCP, it covers browser extensions on Chrome, Edge, Brave, Arc, and Firefox, plus editor plugins in VS Code and its forks. The whole scan happens in one pass, outputs a clean structured list of what it found, and never modifies anything on the machine.

How Perplexity uses it internally

Perplexity has been running Bumblebee internally to protect the systems behind its search product, its Comet browser, and its Computer AI agent. When a new threat surfaces, Perplexity Computer drafts a catalog entry for it, a human reviews and approves it, and Bumblebee runs across all developer machines to check for matches.

Bumblebee started as an internal tool.

Making Perplexity products more secure for users starts with protecting the developer systems we use to build them.

Read the full blog: https://t.co/M2IrAYtfCg

— Perplexity (@perplexity_ai) May 22, 2026

Teams can run their own catalogs the same way. The tool ships with a built-in threat directory seeded from recent supply-chain attacks, including the May 11 campaign. The group behind that attack—tracked by Google under the alias UNC6780—has been running coordinated software poisoning campaigns since at least March 2026.

Bumblebee is available free at github.com/perplexityai/bumblebee under Apache 2.0, which means you can run it, tweak it, improve it and fork it without legal repercussions.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Cryptocurrency & Free Speech Finance

Crypto ticks up as US-Iran peace deal odds climb

4 minutes ago
Cryptocurrency & Free Speech Finance

Crypto PAC Spending Surges in Texas Runoffs, as Prediction Markets Favor Challengers

7 minutes ago
Cryptocurrency & Free Speech Finance

With Central Bank’s Blessing, Georgia Taps Tether for ‘Official’ Stablecoin

13 minutes ago
Cryptocurrency & Free Speech Finance

NEAR price rally gains momentum as cross-chain product activity fuels further 15% jump

1 hour ago
Cryptocurrency & Free Speech Finance

CoinQuant introduces trading infrastructure for the agent economy

1 hour ago
Cryptocurrency & Free Speech Finance

Indonesia blocks Polymarket, calling prediction market online gambling in disguise

2 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Crypto PAC Spending Surges in Texas Runoffs, as Prediction Markets Favor Challengers

7 minutes ago

With Central Bank’s Blessing, Georgia Taps Tether for ‘Official’ Stablecoin

13 minutes ago

NEAR price rally gains momentum as cross-chain product activity fuels further 15% jump

1 hour ago

CoinQuant introduces trading infrastructure for the agent economy

1 hour ago
Latest Posts

Perplexity Built a Tool That Checks Your Computer for Infected Software—Without Setting Off the Infection

1 hour ago

CPJ condemns Tunisia’s judicial harassment of Sonia Dahmani after fresh conviction  

2 hours ago

Indonesia blocks Polymarket, calling prediction market online gambling in disguise

2 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

Crypto ticks up as US-Iran peace deal odds climb

4 minutes ago

Crypto PAC Spending Surges in Texas Runoffs, as Prediction Markets Favor Challengers

7 minutes ago

With Central Bank’s Blessing, Georgia Taps Tether for ‘Official’ Stablecoin

13 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.